Global Protect - Require Machine Cert only for Windows and MAC machines (and all other systems can just use username/password)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect - Require Machine Cert only for Windows and MAC machines (and all other systems can just use username/password)

L1 Bithead

Hi there,

I'm trying to build out a config in my lab where my global protect configuration requires a machine cert and username/password for only Windows OS and MAC OS systems and then for IOS and ANDROID devices, they will only require username/password.  My lab is running an old PA-5050 on PAN OS 8.1.23.  I'm finding that the only option is to enable a certificate profile for ALL systems and we cannot specify specific settings based on OS.

 

Has anyone successfully done this?

 

Alternatively is it possible to configure multiple gateways on the same edge and then use the portal 'agent configuration' to redirect to different gateways that enforce different certificate profiles?

 

I'm also looking at options on PAN OS 9.1.X.

 

Thank you,

 

Michael

1 REPLY 1

L3 Networker

Hi Michael,

 

The Certificate profile config is indeed for all operating systems, but at least in 9.1 the "Allow Authentication with User Credentials OR Client Certificate" setting can be configured per operating system. You could have it like this for example:

 

Cert profile: configured for all
OS Windows: Allow Authentication with User Credentials OR Client Certificate = NO

OS Android: Allow Authentication with User Credentials OR Client Certificate = YES

 

This should result in Windows needing a Client Cert + User Credentials, but Android would need only one or the other.

 

Your second option is also valid. You can use OS in the Config Selection Criteria of the Portal to give a different Portal config to different OS's, and those different Portal configs send them to different Gateways which have different cert profile configs.

 

- DM

Sr. Technical Support Engineer, Strata
  • 1025 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!